CVE-2013-7048: Openstack Nova

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.

Affected products

  • Openstack Nova: from 2013.1, up to and including 2013.1.4; from 2013.2, up to and including 2013.2.1

Published 2014-01-23. Last modified 2026-06-17.